<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't disable windows event collection in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Can-t-disable-windows-event-collection/m-p/37498#M1697</link>
    <description>&lt;P&gt;Did you check all the boxes when you installed the forwarder?  If so, go to the remote machine into where Splunk is installed into etc/apps.  Go to the msicreated/local and see if you have inputs.conf, perfmon.conf, and wmi.conf.  if you remove them and restart the forwarder it should stop.  They may also be in etc/system/local too.&lt;/P&gt;</description>
    <pubDate>Mon, 13 Feb 2012 17:24:26 GMT</pubDate>
    <dc:creator>dmaislin_splunk</dc:creator>
    <dc:date>2012-02-13T17:24:26Z</dc:date>
    <item>
      <title>Can't disable windows event collection</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Can-t-disable-windows-event-collection/m-p/37495#M1694</link>
      <description>&lt;P&gt;I installed the Windows app and updated to 4.2.3 and now I can't disable any of the local event logs it is collecting - which in my case is taking up 500MB + of data a day per machine.&lt;BR /&gt;
Any way around this? What is indexing it behind my back? I have disabled local event log collection from the Data Inputs menu, but they just keep indexing anyway...&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2011 21:55:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Can-t-disable-windows-event-collection/m-p/37495#M1694</guid>
      <dc:creator>grantcasey</dc:creator>
      <dc:date>2011-12-19T21:55:54Z</dc:date>
    </item>
    <item>
      <title>Re: Can't disable windows event collection</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Can-t-disable-windows-event-collection/m-p/37496#M1695</link>
      <description>&lt;P&gt;It could be that the version of the app you are using uses WMI to index the local event logs by default.  Disabling the WMI inputs via Manager or wmi.conf might do the trick.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2011 23:18:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Can-t-disable-windows-event-collection/m-p/37496#M1695</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2011-12-19T23:18:25Z</dc:date>
    </item>
    <item>
      <title>Re: Can't disable windows event collection</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Can-t-disable-windows-event-collection/m-p/37497#M1696</link>
      <description>&lt;P&gt;I have the same problem for remote event logs.   Disabled collection, but they continue to collect.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2012 17:09:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Can-t-disable-windows-event-collection/m-p/37497#M1696</guid>
      <dc:creator>richnavis</dc:creator>
      <dc:date>2012-02-13T17:09:24Z</dc:date>
    </item>
    <item>
      <title>Re: Can't disable windows event collection</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Can-t-disable-windows-event-collection/m-p/37498#M1697</link>
      <description>&lt;P&gt;Did you check all the boxes when you installed the forwarder?  If so, go to the remote machine into where Splunk is installed into etc/apps.  Go to the msicreated/local and see if you have inputs.conf, perfmon.conf, and wmi.conf.  if you remove them and restart the forwarder it should stop.  They may also be in etc/system/local too.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2012 17:24:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Can-t-disable-windows-event-collection/m-p/37498#M1697</guid>
      <dc:creator>dmaislin_splunk</dc:creator>
      <dc:date>2012-02-13T17:24:26Z</dc:date>
    </item>
    <item>
      <title>Re: Can't disable windows event collection</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Can-t-disable-windows-event-collection/m-p/37499#M1698</link>
      <description>&lt;P&gt;I had to uninstall the Windows app from my splunk instance.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2012 18:10:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Can-t-disable-windows-event-collection/m-p/37499#M1698</guid>
      <dc:creator>grantcasey</dc:creator>
      <dc:date>2012-02-13T18:10:23Z</dc:date>
    </item>
    <item>
      <title>Re: Can't disable windows event collection</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Can-t-disable-windows-event-collection/m-p/37500#M1699</link>
      <description>&lt;P&gt;My universial forwarder setup the &lt;CODE&gt;inputs.conf&lt;/CODE&gt; in the &lt;CODE&gt;Program Files\SplunkUniversalForwarder\etc\apps\MSICreated\local&lt;/CODE&gt; path.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2013 22:38:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Can-t-disable-windows-event-collection/m-p/37500#M1699</guid>
      <dc:creator>slierninja</dc:creator>
      <dc:date>2013-08-22T22:38:07Z</dc:date>
    </item>
  </channel>
</rss>

